---
id: CVE-2025-65518
title: >-
  Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of
  Service (DoS) condition
summary: >-
  Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of
  Service (DoS) condition. The vulnerability exists in the get_password.php
  endpoint, where a crafted request containing a malicious payload can cause the
  affected…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-606
vendor: webpros
product: plesk_obsidian
affected:
  - 'plesk_obsidian >= 8.0.1, < 18.0.73'
patched:
  - plesk_obsidian 18.0.73
published: '2026-01-08'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65518'
references:
  - url: 'http://plesk.com'
    label: cve@mitre.org
  - url: 'https://docs.plesk.com/release-notes/obsidian/change-log/'
    label: cve@mitre.org
  - url: 'https://github.com/Jainil-89/CVE-2025-65518/blob/main/cve.md'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/security/cve/CVE-2025-65518'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2428098'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-65518.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - exploit-available
epss: 0.00621
epssPercentile: 0.47501
ingestedAt: '2026-06-30T13:26:50.253Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Jainil-89/CVE-2025-65518'
  checkedAt: '2026-09-25T08:20:48.309Z'
exploitAvailable: true
---

## Overview

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.

## Affected

- `plesk_obsidian >= 8.0.1, < 18.0.73`

## Remediation

Upgrade past the affected range:

- `plesk_obsidian 18.0.73`
